CVE-2021-37593 EXPLOIT
9.1
CRITICAL · CVSS 3.1 · EPSS 5.2% (pctl 92)
Patch early
A public exploit exists.
Description
PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensitive data from the database and possibly modify database data.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 5.16% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-07-30 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| peel | peel shopping |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection | 2021-07-19 |
References
- http://www.netbytesec.com/advisories/UnauthenticatedBlindSQLInjectionVulnerabilityInPEELShopping/
- https://github.com/advisto/peel-shopping/issues/3
- https://github.com/faisalfs10x/CVE-IDs/blob/main/2021/CVE-2021-37593/Proof_of_Concept.md
- http://www.netbytesec.com/advisories/UnauthenticatedBlindSQLInjectionVulnerabilityInPEELShopping/
- https://github.com/advisto/peel-shopping/issues/3
- https://github.com/faisalfs10x/CVE-IDs/blob/main/2021/CVE-2021-37593/Proof_of_Concept.md
→ the Explorer · watch your stack · NVD